Answer in brief
CVE-2026-98363 records a Unknown severity vulnerability in firmware: arm_scpi: reject DVFS OPP count above MAX_DVFS_OPPS. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=8cb7cf56c9fe5412de238465b27ef35b4d2801aa <e9887eeaa138c6b5697af3d2f7c71dc82407b154 || >=8cb7cf56c9fe5412de238465b27ef35b4d2801aa <1aadbef648e92ca642125f188f99b0a26628e3ba || >=8cb7cf56c9fe5412de238465b27ef35b4d2801aa <7daaa684097377b66b98a832de307688a7f3bbc7 || >=8cb7cf56c9fe5412de238465b27ef35b4d2801aa <f17865332cc4ceaac846bcd7c28badbaedfabeff || >=8cb7cf56c9fe5412de238465b27ef35b4d2801aa <0130f9ad3974a5b2ad0fa03d0b300a9fb83ed901 || >=8cb7cf56c9fe5412de238465b27ef35b4d2801aa <69ec03cd481973e4be44a7158ed6c0fa06a9a5f9 || >=8cb7cf56c9fe5412de238465b27ef35b4d2801aa <cc563a59aded6f3b02d75dcc3c0bc5e90755d99e || >=8cb7cf56c9fe5412de238465b27ef35b4d2801aa <32471d84a487c7fd74532bc96be56f8028cf4a3f | e9887eeaa138c6b5697af3d2f7c71dc82407b154, 1aadbef648e92ca642125f188f99b0a26628e3ba, 7daaa684097377b66b98a832de307688a7f3bbc7, f17865332cc4ceaac846bcd7c28badbaedfabeff, 0130f9ad3974a5b2ad0fa03d0b300a9fb83ed901, 69ec03cd481973e4be44a7158ed6c0fa06a9a5f9, cc563a59aded6f3b02d75dcc3c0bc5e90755d99e, 32471d84a487c7fd74532bc96be56f8028cf4a3f |
| Linux/Linuxgeneric | 4.4 | Not reported |
Published upstream
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 6, 2026
In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scpi: reject DVFS OPP count above MAX_DVFS_OPPS scpi_dvfs_get_info() already rejected a zero opp_count, but still trusted any larger value from the SCP firmware. The shared-memory reply only holds MAX_DVFS_OPPS entries in buf.opps[]; a bigger count over-reads that array and then sizes the allocated OPP table incorrectly (garbage OPPs / OOB). The missing upper bound dates back to the original SCPI DVFS support. Reject zero and out-of-range counts in one check and return -EINVAL.
Quoted source text, attributed separately from HOL analysis.